{ "id": "CVE-2024-32256", "sourceIdentifier": "cve@mitre.org", "published": "2024-04-16T17:15:11.050", "lastModified": "2024-04-17T12:48:31.863", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When updating a current package, there are no checks for what types of files are uploaded from the image." }, { "lang": "es", "value": "Phpgurukul Tourism Management System v2.0 es vulnerable a la carga sin restricciones de archivos con tipos peligrosos a trav\u00e9s de /tms/admin/change-image.php. Al actualizar un paquete actual, no se verifican qu\u00e9 tipos de archivos se cargan desde la imagen." } ], "metrics": {}, "references": [ { "url": "https://github.com/jinhaochan/CVE-POC/blob/main/tms/POC.md", "source": "cve@mitre.org" } ] }